Lead Engineer - Malware Reverse Engineering (CTI team)(Remote Or Hybrid
Brooklyn Park, Hennepin County, Minnesota, USA
Listed on 2026-07-31
-
Security
Cybersecurity
The pay range is $ - $
Pay is based on several factors which vary based on position. These include labor markets and in some instances may include education, work experience and certifications. In addition to your pay, Target cares about and invests in you as a team member, so that you can take care of yourself and your family. Target offers eligible team members and their dependents comprehensive health benefits and programs, which may include medical, vision, dental, life insurance and more, to help you and your family take care of your whole selves.
Other benefits for eligible team members include 401(k), employee discount, short term disability, long term disability, paid sick leave, paid national holidays, and paid vacation. Find competitive benefits from financial and education to well-being and beyond at
Working at Target means helping all families discover the joy of everyday life. We bring that vision to life through our values and culture. Learn more about Target here.
As a Lead Engineer - Malware Reverse Engineering you will join a team supporting teams across our Cyber Fusion Center (CFC). This Malware Analysis role is not centered on manually reversing every instruction or task, but instead investigating, researching and implanting new ways we can leverage AI-assisted tooling to triage samples, validate machine-generated analysis and investigate complex or evasive malware where regular automation falls short.
You will develop a strong foundation in reverse engineering while learning how to operate at high scale, analyze attacker tradecraft, think adversarial about both malware and analysis systems as well as translate reverse engineering insights into durable detections across the CFC.
What You Will Work On AI-Augmented Malware Analysis- Review and validate AI-generated static and dynamic analysis results.
- Identify inaccuracies, gaps or adversarial manipulation in automated outputs
- Refine analysis by guiding tools toward deeper behavioral understanding
- Analyze large sample sets and cluster malware into families and campaigns
- Distinguish commodity noise from high-impact or novel threats
- Escalate edge cases requiring deeper manual investigation
- Perform focused reversing on critical code paths (i.e. loaders, unpacking routines, injection logic)
- Analyze obfuscation, packing and anti-analysis techniques
- Investigate unusual or non-standard execution environments (custom VMs, staged payloads)
- Recognize common exploitation patterns (memory corruption, logic flaws, sandbox escapes)
- Assist in reconstructing exploit chains and post-exploitation behavior
- Support root-cause understanding for vulnerabilities observed in the wild
- Contribute to high-quality detection logic (YARA, behavioral rules, heuristics)
- Extract stable, meaningful indicators from reversed samples
- Collaborate with detection engineers to ensure resilience against evasion
- Work with automated analysis pipelines (static, dynamic, emulation)
- Assist in improving analysis workflows and signal quality
- Leverage Python scripting to extend or customize tooling
Core responsibilities of this job are described within this job description. Job duties may change at any time due to business needs.
About You- 4 year degree or equivalent experience
- 7+ years of software or security engineering experience preferably in malware labs, CTFs or with personal research projects
- Demonstrated understanding of reverse engineering concepts (x86/x64, assembly, calling conventions)
- Familiarity with common malware techniques (packing, persistence, process injection)
- Demonstrated programming knowledge in C/C++ and Python
- Familiarity with YARA or other detection frameworks
- Experience with tools like Ghidra, IDA Pro, Binary Ninja or similar
- Exposure to dynamic analysis (debugging, sandboxing, instrumentation)
- Understanding of OS internals (Windows or Linux), including processes, memory, and system calls
- Basic networking knowledge (protocols, common attack surfaces)
- Ability to reason…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).